The €403 million in penalties that Ireland's Data Protection Commission imposed on Google today rests on arguments first put to European regulators in November 2018, when seven consumer groups accused the company of steering Android owners into sharing their whereabouts and then using that information for advertising without a valid legal basis. Set against the findings published today, the complaint shows where the regulator followed the consumer groups, where it went beyond them, and what it has yet to explain.
In Short
In 2018, consumer groups in seven European countries complained that Google pushed people with Android phones into letting it record where they went, and then used that record to show them ads without proper permission. Ireland's privacy regulator decided today that Google did break Europe's data rules in how it handled location information, which matters to anyone in Europe with a Google account or an Android phone and to the advertisers whose targeting and measurement draw on that data. Google now has six months to change how it processes the data, but the regulator has not yet published its full reasoning, so it is not yet possible to say exactly which of the complaint's arguments it accepted.
A template, seven filings
On 27 November 2018, consumer organisations in seven countries said they would file complaints against Google with their national data protection authorities, according to BEUC, the Brussels-based European Consumer Organisation. The seven were Forbrukerrådet in Norway, Consumentenbond in the Netherlands, Ekpizo in Greece, dTest in the Czech Republic, Zveza Potrošnikov Slovenije in Slovenia, Federacja Konsumentów in Poland and Sveriges Konsumenter in Sweden. Others took different routes. Denmark's Forbrugerrådet Tænk planned to report the practices to the Danish data protection body, Germany's vzbv was weighing an injunction, and the Transatlantic Consumer Dialogue intended to raise the matter with the US Federal Trade Commission, according to BEUC.
The document reviewed for this article is the template those filings followed. It carries placeholders where the authority, the consumer organisation and the complainant would be named, uses bracketed pronouns for the data subject, and is undated. It is lodged under Article 80(1) of the GDPR, which allows a non-profit body to act on an individual's mandate, and it names Google LLC, at Amphitheatre Parkway in Mountain View, as the respondent. Its evidence base is the Forbrukerrådet report "Every Step You Take: How deceptive design lets Google track users 24/7", dated November 2018 and attached as the first appendix. Google's privacy policy and terms of service form the second and third.
The complainant described in the template owns an Android smartphone linked to a Google account. The consumer groups asked the authority to examine Google's compliance with Articles 5, 6, 7, 12, 13 and 25 of the regulation, and they aimed at two account settings: Location History and Web & App Activity. Location Accuracy, the third feature in today's decision, does not appear anywhere in the text.
Google rejected the characterisation at the time. A company spokesman told Reuters that Location History was off by default and could be edited, deleted or paused at any point, according to The Next Web's report of 27 November 2018.
What the settings recorded
Much of the complaint is a close description of the two products as they appeared on Android handsets in 2018. Location History, it says, derived position from GPS, Wi-Fi scanning and Bluetooth scanning, which let Google place a user inside buildings as well as outdoors. Once enabled, the setting collected the mode of transport (walking, driving, riding a tram, entering a vehicle), barometric pressure as a proxy for altitude, Wi-Fi information, GPS coordinates and the device's battery level. Some of this was visible to users in the Location History Timeline. The barometric readings, nearby Wi-Fi hotspots, Bluetooth beacons and battery data were, according to the complaint, collected passively in the background and never displayed.
Web & App Activity worked differently. Most apps did not record location through it, the complaint acknowledges, but Google searches and searches in Google Maps were logged together with the place where the user stood when typing the query. Those records sat in a separate "My Activity" log, kept apart from the Timeline.
What was the data for? The complaint answers with Google's own words, taken from the company's activity controls page: "This data helps Google give you more personalized experiences across Google services, like a map of where you've been, tips about your commute, recommendations based on places you've visited, and useful ads, both on and off Google." The final clause carried the case. Advertising "off Google" extends beyond Search, Maps and YouTube to the third-party sites and apps where Google places ads.
From Mountain View to Dublin
The complaint went to seven authorities, but it did not stay with them. On 22 January 2019, Google Ireland Limited became the data controller for users in the European Economic Area and Switzerland, replacing Google LLC, according to Google's blog post on the change. Google said the change was intended to ease engagement with European authorities through the GDPR's one-stop-shop mechanism and did not alter how its products worked or how it collected data. From that point, the mechanism pointed cross-border complaints about Google's EEA processing towards the Irish authority.
The timing was notable. A day earlier, on 21 January 2019, France's CNIL had fined Google LLC €50 million over Android account creation, a case in which the French authority concluded that the Irish regulator was not the lead authority for that processing, according to Privacy International.
The DPC opened its own inquiry on 4 February 2020, under Section 110 of Ireland's Data Protection Act 2018 and the Article 60 cooperation procedure, according to TechCrunch's report that day. The authority described the concerns it had received as relating to the legality of Google's processing of location data and the transparency surrounding it. The inquiry opened 434 days after the consumer groups went public, and its opening date also closes the window it examined, which runs from 25 May 2018.
The pace drew complaints of its own. When BEUC published a report on barriers to cross-border GDPR enforcement in November 2020, the location complaints were still unresolved two years after filing, according to TechCrunch. Today's decision arrives 2,855 days after the complaints were made public, a gap of seven years and nearly ten months.
One question the DPC statement leaves open concerns the calendar. The inquiry window starts on 25 May 2018, which is 242 days before Google Ireland Limited became the controller under Google's own policy. The decision is addressed to Google Ireland Limited, and the statement does not explain how processing in those earlier months was attributed. The full decision, which the DPC says it will issue in due course, is the document likely to settle it.
Lawfulness and fairness: the core of the case
The DPC found that Google infringed the requirements of lawfulness and fairness in its processing of location data through Web & App Activity and Location History. That is the ground on which the consumer groups spent most of their pages, though they built it without knowing which legal basis Google relied upon. The complaint says it would "preliminary assume" consent for Location History, since the feature required an opt-in. Web & App Activity, switched on by default, pointed either to consent obtained by pressure or to reliance on legitimate interests.
Consent that was not freely given
For Location History, the argument rested on the regulation's definition of consent in Article 4(11), which the complaint quotes as "any freely given, specific, informed and unambiguous indication". The consumer groups argued that none of the four elements held.
Repetition was the most concrete allegation. Users who declined Location History during setup, according to the complaint, "must decline the activation of the setting at least four times when using different services that are preinstalled on Android phones; in Google Assistant, Google Maps, Google Search App, and Google Photos." Bundling came next. A user who simply wanted photographs grouped by place had to switch on Location History in full, including its advertising uses. The complaint called this a bundled "take it or leave it" option, and said enabling Google Assistant carried the same consequence.
Interface design ran through the rest. The Android setup sequence, the complaint contends, was built so that a user following the natural click-flow ended up consenting; the advertising use appeared only behind a "Learn more" link; and attempts to pause the setting brought vague warnings about lost functionality. The Forbrukerrådet research described these techniques as deceptive design, a family of practices now more commonly discussed as dark patterns.
Market power featured too. The complaint cited Recital 43 of the GDPR for the principle that consent is not a valid ground where there is a clear imbalance between the parties, and argued that "Google is clearly in a dominant position when 85% of global smart phones are running on the Android operating system, which is a Google product". The figure, credited to IDC, is the complaint's own; the DPC statement makes no reference to market share. Google's position in Android has also been tested under competition law, where the Court of Justice of the European Union dismissed Google's appeal against the €4.125 billion Android fine in July 2026.
A point in Google's favour sits in the complaint's own exhibits. Its screenshot of the Android account setup page shows Location History with "Don't save my Location History to my Google Account" already selected, which is consistent with the company's position that the feature was off by default. The same series of screenshots shows Web & App Activity set the opposite way, with "Save my Web & App Activity to my Google Account" pre-selected.
Web & App Activity, switched on at the start
That default was the centre of the second argument. The complaint states that Web & App Activity was enabled by default when an account was created and cites the GDPR and Article 29 Working Party guidance for the rule that "Pre-ticked boxes or any other method of consent by default are not to be used." At setup, the feature was described as saving "your searches, Chrome browsing history and activity from sites and apps that use Google services". That location data was involved became clear, the complaint says, only after tapping "More options" and then "Learn more". Pausing the setting produced a warning that users "may stop seeing more relevant search results or recommendations that you care about".
The consumer groups then tried to close off the two alternatives. Performance of a contract under Article 6(1)(b) failed, they argued, because Google never claimed the processing was necessary to deliver its services, and the fact that a user could pause the setting suggested it was not. Legitimate interests under Article 6(1)(f) failed the balancing test: collection happened without any user interaction, data was kept on a seemingly indefinite basis, it fed advertising, and users had no reasonable expectation of any of it. The complaint cited the Article 29 Working Party's Opinion 06/2014, which held that "opt-in consent would almost always be required [...] for tracking and profiling for purposes of direct marketing, behavioural advertisement, location-based advertising or tracking-based digital market research".
European practice has moved towards that view since. In December 2022 the European Data Protection Board found contract unsuitable as a legal basis for Meta's behavioural advertising, and on 27 October 2023 it instructed the DPC to ban such processing on the basis of contract and legitimate interest across the European Economic Area. IAB Europe's Transparency and Consent Framework, the specification many consent management platforms implement, withdrew legitimate interest as a basis for its profiling and personalisation purposes in version 2.2, released on 16 May 2023. And an EDPB-commissioned review of 62 one-stop-shop decisions and five binding decisions on legitimate interest, adopted between December 2018 and June 2025, found controllers systematically underestimating what the balancing test requires.
Which legal basis Google actually relied on for each purpose, and on which of these arguments the DPC decided, remains unstated. The statement says only that the processing breached the principles of lawfulness and fairness.
Transparency across three features
The second finding, breaches of Google's transparency obligations in all three features, maps onto an argument the consumer groups pitched at the level of the privacy policy. According to the complaint, Google listed four of the six legal bases in Article 6 - consent, legitimate interest, provision of a service and legal obligations - with examples under each. The policy said Google asked for consent to provide personalised services such as ads, yet it also listed advertising among the company's legitimate interests. That left it unclear, the complaint argued, which basis applied to behavioural targeting, and the information was not given during account setup either.
The complaint presents the problem as a long-running one. It says the Article 29 Working Party raised the same concern when Google merged the privacy policies of its services in 2012, and that the company continued to provide unclear and incomplete information after the GDPR took effect. It also takes issue with a single adjective. The setup screen described Location History as saving a "private map" of where the user went, prompting the complaint to ask: "What does 'private' mean in this context, when Google has access to all the data and can use it for other purposes beyond the creation of the map?"
France had already acted on closely related screens. The CNIL's €50 million penalty in January 2019 was imposed for lack of transparency, inadequate information and lack of valid consent regarding ads personalisation, following group complaints filed by noyb and La Quadrature du Net on 25 and 28 May 2018, according to the EDPB's summary of the French decision. The CNIL found information diluted across several documents and consent that was neither specific nor unambiguous, with the relevant options hidden behind a "More options" button. The boxes governing ad personalisation were pre-checked by default, according to law firm Hunton Andrews Kurth's account of the ruling. The same account-creation flow drew a second French penalty when the CNIL fined Google €325 million on 1 September 2025, in part because users creating an account were presented with an imbalanced choice over advertising cookies.
Retention: in the facts, not in the requests
The retention finding, which covers Web & App Activity and Location History, is the one the consumer groups did not formally seek. Their list of requests asks the authority to rule on legal basis and information, on the Article 7 consent conditions, on legitimate interests, and on whether Google's design patterns were compatible with Articles 5(1)(a) and 25. Storage periods appear only in the factual narrative and the balancing argument. "Location History data is seemingly retained indefinitely if the user does not manually delete it," the complaint says, adding that deleting historical data was a separate process from pausing the feature.
The DPC nonetheless treated retention as a distinct infringement. Deputy Commissioner Graham Doyle said keeping users' location data for longer than necessary made their loss of control over it worse, according to the DPC.
Google's defence engages this point most directly. A company spokesperson said the case concerns historical policies that have since been updated, and that from 2019 onwards Google significantly changed its practices and added tools that make location data simpler to manage, according to NewsIreland.EU. Those changes began after the complaint was filed but partly inside the window the inquiry examined. Whether they satisfy a six-month compliance order framed around the 2018 to 2020 products is something the published statement does not address.
Location Accuracy: outside the complaint's text
The fourth finding concerns a feature the consumer groups never named. Location Accuracy is part of the Android operating system rather than an account setting, and it lets a device fix its position more precisely than GPS alone would allow, according to the DPC. It is available to Android users whether or not they hold a Google Account. The DPC found that Google breached its accountability obligations because it could not demonstrate that its processing of personal data in Location Accuracy complied with the principle of lawfulness, fairness and transparency.
The closest the complaint comes is a passing reference to the Android control that turns device location services on and off, which it cites as evidence that Google could personalise services without location data. The feature's presence in the decision reflects the reach of an own-volition inquiry, in which the authority, not the complainant, sets the scope. The distinction between complaint-based and own-volition inquiries was argued by Meta before Ireland's High Court in a separate case, and Justice Siobhán Phelan rejected all of Meta's grounds on 21 May 2026, holding that Article 83 requires fines to account for the number of data subjects affected however an inquiry begins.
What the consumer groups asked for
Section D of the complaint set out four questions: whether Google had a lawful basis for processing location data, particularly for advertising, and whether it told users which basis it used; whether the Article 7 conditions for valid consent were met; whether legitimate interests could serve as a basis; and whether Google's design choices were compatible with fairness, transparency and data protection by design and by default. It then asked the authority to stop any unlawful processing, "notably those operations related to the use of such data for advertising purposes", and to impose "an effective, proportionate and deterrent fine".
On the first three, the DPC's lawfulness and transparency findings give the consumer groups much of what they sought, subject to the reasoning still to be published. On the fourth, the statement is silent: it does not mention Article 25, design patterns or the setup screens. The complaint also asked that the matter go to the European Data Protection Board if appropriate. The DPC thanked its peer supervisory authorities for their cooperation and did not describe any objections or a referral to the Board.
The fine factors the complaint proposed were specific. It asked the authority to weigh the number of users affected, potentially anyone with an Android phone or a Google account; the sensitivity of location data; Google's status as what it called a "repeat offender"; the financial gains from processing personal data for advertising; and the company's dominant market power. The DPC has not broken the €403 million down by infringement or explained how it was calculated.
A sense of scale comes from Article 83 of the GDPR, which caps fines for breaches of the basic principles at €20 million or 4% of an undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher. In its separate Hive inquiry, the DPC told Meta that the cap would be calculated by reference to the Meta group as a whole rather than the Irish subsidiary, according to the High Court judgment. Alphabet reported annual revenues above $400 billion for the first time for 2025. Measured against that figure, the penalty, about $463 million according to Reuters, amounts to about 0.1%, while a group-level cap would sit above $16 billion. It is nonetheless the fourth-largest fine the DPC has imposed, out of more than €4 billion it has levied since becoming lead regulator for most large US technology firms, according to Reuters.
The complainants' response was mixed. BEUC's director general Agustín Reyna welcomed the decision but said the time taken was out of proportion to the seriousness of the infringement, warning that late enforcement can be as harmful as none, according to NewsIreland.EU. BEUC also said Google had made changes globally after the original complaint, but that further concerns had prompted a second complaint in 2022. Finn Myrstad, digital policy director at the Norwegian Consumer Council, described the ruling as an important milestone, according to Invezz.
The Norwegian council has been a recurring source of such cases. Its 2020 complaint against Grindr, which covered the sharing of HIV status and location data with advertisers, ended in a 65 million kroner fine that Oslo District Court upheldin July 2024. On 3 June 2026 it joined noyb in a complaint against Schibsted's pay-or-okay model. BEUC, for its part, coordinated national complaints to data protection authorities over Meta's consent-for-ads model in February 2024.
Why the location question reaches advertisers
The advertising relevance is written into the complaint's central quotation. "Useful ads, both on and off Google" describes location data flowing into targeting across Google's own properties and its network. Doyle made the same connection today, saying users could have been unaware that their location was being used to influence them with ads or to infer their interests, according to the DPC.
Measurement depends on the same signals. Google's store visits conversions, its implementation of footfall attribution, are modelled from signed-in users with location history enabled who interact with an ad and later visit a business, with Google extrapolating from those observed cases to the wider exposed audience. Google's consumer product has since shifted: Maps Timeline, first detailed in December 2023 and rolled out through 2024, moved history storage onto the device and cut default retention from 18 months to three. Google's advertising documentation still describes an account-level location history opt-in, and the company has not publicly reconciled the two.
American litigation has attacked the same settings from the other end. A San Francisco jury ordered Google to pay $425.7 million on 3 September 2025 in a class action over data gathered after users switched Web & App Activity off. Google settled a case for $62 million in May 2024 over allegations that it tracked users after Location History was turned off, and Texas secured a $1.375 billion privacy settlement that included Location History claims. Those cases asked whether switching the settings off actually stopped collection. The European complaint asked a different question: how the settings came to be switched on in the first place, and what users were told when they were.
Durability is the remaining uncertainty. An analysis by Alliance Risk found that nearly 40% of the €7.1 billion in GDPR fines issued since 2018 had been annulled or were under active challenge. In March 2026 a Luxembourg court annulled Amazon's €746 million fine, a penalty imposed because interest-based advertising lacked a valid legal basis, on the grounds that the regulator had not assessed fault or justified why a fine was the right corrective measure. The Google statement reported today does not say whether the company will challenge the DPC's decision.
If the six-month compliance period runs from today, it would end on 21 March 2027. The statement does not specify the starting point.
Timeline
- 2012 - The Article 29 Working Party raises transparency concerns when Google merges the privacy policies of its services, according to the complaint.
- 25 May 2018 - The GDPR becomes applicable; the DPC's inquiry window opens.
- 25 and 28 May 2018 - noyb and La Quadrature du Net file group complaints with France's CNIL over Google's ads personalisation.
- November 2018 - Forbrukerrådet publishes "Every Step You Take: How deceptive design lets Google track users 24/7".
- 27 November 2018 - Consumer groups in seven countries say they will file GDPR complaints against Google LLC over Location History and Web & App Activity.
- 21 January 2019 - The CNIL fines Google LLC €50 million over transparency and consent during Android account creation.
- 22 January 2019 - Google Ireland Limited becomes data controller for users in the EEA and Switzerland.
- January 2020 - The Norwegian Consumer Council and noyb file complaints over Grindr's disclosures of personal data to advertisers.
- 4 February 2020 - The DPC opens its own-volition inquiry into Google Ireland Limited; the inquiry window closes.
- November 2020 - BEUC publishes a report on cross-border GDPR enforcement barriers while the Google location complaints remain unresolved.
- December 2022 - The EDPB finds contract unsuitable as a legal basis for Meta's behavioural advertising.
- 27 October 2023 - The EDPB instructs the DPC to ban Meta's behavioural advertising processing based on contract and legitimate interest.
- February 2024 - BEUC coordinates complaints to data protection authorities over Meta's consent-for-ads model.
- May 2024 - Google settles a US case for $62 million over tracking after Location History was turned off.
- 1 July 2024 - Oslo District Court upholds the 65 million kroner Grindr fine.
- 1 September 2025 - The CNIL fines Google €325 million over Gmail ads and cookie consent during account creation.
- 3 September 2025 - A San Francisco jury orders Google to pay $425.7 million in a Web & App Activity class action.
- 4 February 2026 - Alphabet reports 2025 results, with annual revenues above $400 billion for the first time.
- March 2026 - A Luxembourg court annuls Amazon's €746 million GDPR fine.
- March 2026 - An EDPB-commissioned digest reviews 62 one-stop-shop decisions on legitimate interest.
- 21 May 2026 - Ireland's High Court dismisses Meta's challenge to the DPC's Hive inquiry.
- Late May 2026 - Alliance Risk finds nearly 40% of €7.1 billion in GDPR fines annulled or under challenge.
- 3 June 2026 - The Norwegian Consumer Council and noyb file a complaint against Schibsted's pay-or-okay model.
- July 2026 - The Court of Justice of the European Union dismisses Google's appeal against the €4.125 billion Android fine.
- 21 September 2026 - The DPC imposes fines totalling €403 million on Google Ireland Limited and orders its processing into compliance within six months.
- 21 March 2027 - The six-month compliance period ends, if counted from the date of the DPC's statement.
Related PPC Land coverage
- Irish regulator fines Google €403 million over location data processing - PPC Land's report on the decision itself, covering the four findings, the penalty's ranking and the six-month order.
- Google loses 4.1 billion Android fine as EU court dismisses appeal - The competition-law judgment on Google's conduct in the Android ecosystem.
- EDPB takes unprecedented action against Meta: Bans behavioral advertising data processing across EEA - The urgent binding decision that ruled out contract and legitimate interest for Meta's behavioural advertising.
- EDPB's damning digest: how 'legitimate interest' fails in practice - Analysis of how the balancing test has been applied across 62 one-stop-shop decisions.
- Google fined €325 million by French regulator for Gmail ads and cookie violations - The CNIL decision on consent choices during Google account creation.
- Irish High Court throws out Meta's challenge to €360-430M DPC fine - The judgment on inquiry scope and on counting affected users when setting fines.
- Luxembourg court annuls Amazon's €746M GDPR fine, sends case back to regulator - How a fine over advertising legal basis was undone on procedural grounds.
- Eight years of GDPR: 40% of the €7.1B in fines annulled or under challenge - Enforcement data separating headline penalties from those that survive appeal.
- Google ordered to pay $425.7 million in privacy violation verdict - The US jury verdict over data collection after users disabled Web & App Activity.
- Texas secures $1.375 billion from Google in privacy settlement - The state settlement that included Location History allegations.
- Meta's consent-for-ads model still falls short, says EU consumer body - BEUC's legal analysis and its record of coordinated national complaints.
- Schibsted's pay-or-okay system in Norway triggers formal GDPR complaint - The Norwegian Consumer Council's most recent joint complaint over advertising consent.
- Grindr fined 65 million kroner for sharing sensitive user data - An earlier Norwegian Consumer Council case involving location data shared with advertisers.
Summary
Who: Ireland's Data Protection Commission, through Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney, against Google Ireland Limited. The inquiry followed complaints coordinated by BEUC and filed by consumer organisations in Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland and Sweden, built on research by Forbrukerrådet. The complaint template named Google LLC; Google Ireland Limited became the EEA data controller on 22 January 2019.
What: A final decision imposing fines totalling €403 million and a six-month compliance order, with findings on lawfulness and fairness in Web & App Activity and Location History, transparency in all three examined features, retention in Web & App Activity and Location History, and accountability in Location Accuracy. The 2018 complaint argued that consent for Location History was not freely given, specific, informed or unambiguous, that Web & App Activity was enabled by default, and that neither contract nor legitimate interests could justify using location data for advertising. It did not mention Location Accuracy and did not formally request a retention finding.
When: The DPC made the decision public today, 21 September 2026. The complaints were made public on 27 November 2018, the inquiry opened on 4 February 2020, and the period examined runs from 25 May 2018 to 4 February 2020.
Where: The decision was taken in Dublin by Google's lead supervisory authority and concerns processing of the personal data of Google account holders and Android users across the European Economic Area.
Why: According to the DPC, Google's failures meant people could have been unaware that their location was being used to influence them with ads or to infer their interests, and keeping the data longer than necessary deepened the loss of control. The complaint traced that outcome to setup screens that pre-selected Web & App Activity, repeated prompts to enable Location History, bundled features, and a privacy policy that did not say which legal basis covered advertising. For advertisers, the same settings feed Google's location-based targeting and store visits measurement.
Discussion